summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-discuss/20120208/006446.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-discuss/20120208/006446.html')
-rw-r--r--zarb-ml/mageia-discuss/20120208/006446.html119
1 files changed, 119 insertions, 0 deletions
diff --git a/zarb-ml/mageia-discuss/20120208/006446.html b/zarb-ml/mageia-discuss/20120208/006446.html
new file mode 100644
index 000000000..a3e6146b9
--- /dev/null
+++ b/zarb-ml/mageia-discuss/20120208/006446.html
@@ -0,0 +1,119 @@
+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
+<HTML>
+ <HEAD>
+ <TITLE> [Mageia-discuss] A possible risk ?
+ </TITLE>
+ <LINK REL="Index" HREF="index.html" >
+ <LINK REL="made" HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20A%20possible%20risk%20%3F&In-Reply-To=%3CCAJyy6UTzVGkkJU-74o_fogfKTRPEsUsvgM24h-Wen5JO_DfoeA%40mail.gmail.com%3E">
+ <META NAME="robots" CONTENT="index,nofollow">
+ <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
+ <LINK REL="Previous" HREF="006445.html">
+ <LINK REL="Next" HREF="007767.html">
+ </HEAD>
+ <BODY BGCOLOR="#ffffff">
+ <H1>[Mageia-discuss] A possible risk ?</H1>
+ <B>Diego Bello</B>
+ <A HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20A%20possible%20risk%20%3F&In-Reply-To=%3CCAJyy6UTzVGkkJU-74o_fogfKTRPEsUsvgM24h-Wen5JO_DfoeA%40mail.gmail.com%3E"
+ TITLE="[Mageia-discuss] A possible risk ?">dbello at gmail.com
+ </A><BR>
+ <I>Wed Feb 8 19:08:55 CET 2012</I>
+ <P><UL>
+ <LI>Previous message: <A HREF="006445.html">[Mageia-discuss] A possible risk ?
+</A></li>
+ <LI>Next message: <A HREF="007767.html">[Mageia-discuss] A possible risk ?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#6446">[ date ]</a>
+ <a href="thread.html#6446">[ thread ]</a>
+ <a href="subject.html#6446">[ subject ]</a>
+ <a href="author.html#6446">[ author ]</a>
+ </LI>
+ </UL>
+ <HR>
+<!--beginarticle-->
+<PRE>On Wed, Feb 8, 2012 at 11:39 AM, Wolfgang Bornath
+&lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">molch.b at googlemail.com</A>&gt; wrote:
+&gt;<i> 2012/2/8 Diego Bello &lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">dbello at gmail.com</A>&gt;:
+</I>&gt;&gt;<i> On Wed, Feb 8, 2012 at 11:01 AM, Wolfgang Bornath
+</I>&gt;&gt;<i> &lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">molch.b at googlemail.com</A>&gt; wrote:
+</I>&gt;&gt;&gt;<i> 2012/2/8 Anne Wilson &lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">annew at kde.org</A>&gt;:
+</I>&gt;&gt;&gt;&gt;<i> On Wednesday 08 February 2012 15:13:57 Anne Wilson wrote:
+</I>&gt;&gt;&gt;&gt;&gt;<i> Yes, I have seen postings like &quot;why do I have to use passwords&quot; and
+</I>&gt;&gt;&gt;&gt;&gt;<i> &quot;why can I not log in KDE as root&quot; more than once. Are these people
+</I>&gt;&gt;&gt;&gt;&gt;<i> our target group? If so than - have fun! What strikes me is that you
+</I>&gt;&gt;&gt;&gt;&gt;<i> of all people are advocating a loosening of security with no real
+</I>&gt;&gt;&gt;&gt;&gt;<i> reason.
+</I>&gt;&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;&gt;<i> I do not want to have to give the root password to members of my family that
+</I>&gt;&gt;&gt;&gt;<i> are, frankly, clueless on tech-matters. &#160;At the same time, I do want them to
+</I>&gt;&gt;&gt;&gt;<i> apply at least security updates. &#160;Being able to accept updates from a trusted
+</I>&gt;&gt;&gt;&gt;<i> source (direct from Mageia) with only their user password is the safest their
+</I>&gt;&gt;&gt;&gt;<i> systems can have.
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;<i> I understand the reasons. But you know as well as everybody else that
+</I>&gt;&gt;&gt;<i> sometimes updates do not work as easy as they should. It could be
+</I>&gt;&gt;&gt;<i> caused by a faulty mirror or by a glitch in a package (which should
+</I>&gt;&gt;&gt;<i> not happen but &quot;should not happen&quot; implies &quot;can happen&quot;) or whatever
+</I>&gt;&gt;&gt;<i> other reason. Then your family members will wait for you anyway (in
+</I>&gt;&gt;&gt;<i> the best case) without knowing what happened - while they could have
+</I>&gt;&gt;&gt;<i> been happily working or entertaining themselves until you come and do
+</I>&gt;&gt;&gt;<i> the updates.
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;<i> Apart from the understandable quest to make it easy on the unwashed
+</I>&gt;&gt;&gt;<i> masses - it is still a security break - see what I have written about
+</I>&gt;&gt;&gt;<i> the ability of xguest to do updates (while xguest was invented to
+</I>&gt;&gt;&gt;<i> leave the system without garbage or damage at the end of his/her
+</I>&gt;&gt;&gt;<i> session).
+</I>&gt;&gt;&gt;<i>
+</I>&gt;&gt;&gt;<i> --
+</I>&gt;&gt;&gt;<i> wobo
+</I>&gt;&gt;<i>
+</I>&gt;&gt;<i> A bad update will break your system no matter if you are root or not.
+</I>&gt;<i>
+</I>&gt;<i> That's actually a point in favor of the need for the root password -
+</I>&gt;<i> if the system breaks: the user can not do anything at all - instead he
+</I>&gt;<i> will have to go for a walk until root comes to fix the problem. So why
+</I>&gt;<i> do you insist on letting poor user take that risk by default?
+</I>&gt;<i>
+</I>&gt;<i> --
+</I>&gt;<i> wobo
+</I>
+Because a simple update should not break the system. They should work
+all the time, just like printers or the Internet connection :p.
+
+Now, seriously talking, I have installed updates with my user all the
+time and never had a problem. This case is an exception and I don't
+thing of it as a bug, except for the feature that it can be done by a
+guest user.
+
+
+
+--
+Diego Bello Carre&#241;o
+</PRE>
+
+
+
+
+
+
+<!--endarticle-->
+ <HR>
+ <P><UL>
+ <!--threads-->
+ <LI>Previous message: <A HREF="006445.html">[Mageia-discuss] A possible risk ?
+</A></li>
+ <LI>Next message: <A HREF="007767.html">[Mageia-discuss] A possible risk ?
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#6446">[ date ]</a>
+ <a href="thread.html#6446">[ thread ]</a>
+ <a href="subject.html#6446">[ subject ]</a>
+ <a href="author.html#6446">[ author ]</a>
+ </LI>
+ </UL>
+
+<hr>
+<a href="https://www.mageia.org/mailman/listinfo/mageia-discuss">More information about the Mageia-discuss
+mailing list</a><br>
+</body></html>